CVE-2018-16763

CRITICAL EXPLOITED IN THE WILD NUCLEI

FUEL CMS 1.4.1 - RCE

Title source: llm

Description

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

Exploits (30)

exploitdb WORKING POC
by Padsala Trushal · pythonwebappsphp
https://www.exploit-db.com/exploits/50477
exploitdb WORKING POC
by Alexandre ZANNI · rubywebappsphp
https://www.exploit-db.com/exploits/49487
exploitdb WORKING POC
by 0xd0ff9 · pythonwebappslinux
https://www.exploit-db.com/exploits/47138
nomisec WORKING POC 23 stars
by p0dalirius · remote
https://github.com/p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE
nomisec WORKING POC 5 stars
by padsalatushal · remote
https://github.com/padsalatushal/CVE-2018-16763
nomisec WORKING POC 4 stars
by n3m1sys · poc
https://github.com/n3m1sys/CVE-2018-16763-Exploit-Python3
nomisec WORKING POC 3 stars
by shoamshilo · remote
https://github.com/shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--
nomisec WORKING POC 2 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2018-16763
nomisec WORKING POC 2 stars
by not1cyyy · remote
https://github.com/not1cyyy/CVE-2018-16763
nomisec WORKING POC 2 stars
by kxisxr · remote
https://github.com/kxisxr/Bash-Script-CVE-2018-16763
nomisec WORKING POC 2 stars
by hikarihacks · remote
https://github.com/hikarihacks/CVE-2018-16763-exploit
nomisec WORKING POC 1 stars
by kaxm23 · remote
https://github.com/kaxm23/exploit_cms_fuel
nomisec WORKING POC 1 stars
by dinhbaouit · remote
https://github.com/dinhbaouit/CVE-2018-16763
nomisec WORKING POC
by estebanzarate · poc
https://github.com/estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC
github WRITEUP
by Zahid-secure · poc
https://github.com/Zahid-secure/cve-walkthrough-labs/tree/main/2018/CVE-2018-16763-ignite-fuelcms
gitlab WORKING POC
by uwueviee · remote
https://gitlab.com/uwueviee/fu3lf1lt3r
gitlab WORKING POC
by python-projects7372210 · poc
https://gitlab.com/python-projects7372210/cve-2018-16763-proof-of-concept
nomisec WORKING POC
by Cyberuser-hash · remote
https://github.com/Cyberuser-hash/CVE-2018-16763
nomisec WORKING POC
by bad-c0de · poc
https://github.com/bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE
nomisec WORKING POC
by B7T3 · poc
https://github.com/B7T3/CVE-2018-16763_FuelCMS-1.4.1_RCE
nomisec WRITEUP
by ArtemCyberLab · poc
https://github.com/ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-
nomisec WORKING POC
by saccles · remote
https://github.com/saccles/CVE_2018_16763_Proof_of_Concept
nomisec WORKING POC
by altsun · remote
https://github.com/altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE
nomisec WORKING POC
by VitoBonetti · remote
https://github.com/VitoBonetti/CVE-2018-16763
nomisec STUB
by antisecc · poc
https://github.com/antisecc/CVE-2018-16763
nomisec WORKING POC
by BrunoPincho · poc
https://github.com/BrunoPincho/cve-2018-16763-rust
nomisec WORKING POC
by wizardy0ga · remote
https://github.com/wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763
nomisec WORKING POC
by uwueviee · poc
https://github.com/uwueviee/Fu3l-F1lt3r
vulncheck_xdb WORKING POC
remote
https://github.com/1337kid/Exploits
vulncheck_xdb WORKING POC
remote
https://github.com/n3rdh4x0r/CVE-2018-16763

Nuclei Templates (1)

FUEL CMS 1.4.1 - Remote Code Execution
CRITICALby pikpikcu
Shodan: http.title:"fuel cms"
FOFA: title="fuel cms"

Scores

CVSS v3 9.8
EPSS 0.9391
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-05-26
InTheWild.io 2022-05-26
CWE
CWE-74
Status published
Products (1)
thedaylightstudio/fuel_cms < 1.4.2
Published Sep 09, 2018
Tracked Since Feb 18, 2026